Attackers are attempting to target X users following the launch of X Money, prompting the platform to investigate a wave of suspicious activity. After numerous users reported receiving unsolicited password reset emails, an X representative said the company was actively investigating but had not yet found evidence that any hacks succeeded.
On Tuesday, X product engineer Mridul Singhai posted to the social network acknowledging the flood of user complaints about mass password reset attempts. He explained the likely motivation behind the surge, writing that attackers appear to believe that now that X Money is widely available, they can gain unauthorized access to accounts. Since the investigation remains ongoing, the company found no evidence of any breaches while apologizing for the multiple emails users received.
Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts. We are actively investigating the issue and, so far, have found no evidence of any breaches.
We apologize for the multiple emails and appreciate your patience… https://t.co/zf1pRWbqBX
— Mridul Singhai (@singhai) September 1, 2026
X Money represents X’s newly launched payments service, which includes a bank card alongside other financial benefits. Because the service aims to make it easier for creators to collect payments directly on the platform, it further facilitates X’s broader ambition of building an integrated digital economy. However, money changing hands tends to attract bad actors, which appears to be exactly what happened following the rollout.
The company has not posted details to any official X account, nor responded to press inquiries at the time of reporting. However, X general counsel James Burnham issued a stern warning, stating that the legal and security teams would stop at nothing to identify, locate, and hold criminally accountable anyone attempting to victimize the platform’s users.
As the attacks continued, users began warning each other about the problem while reminding others to enable two-factor authentication for added protection. X’s chatbot Grok also replied to several posts with instructions on enabling security features, confirming that attackers were mass-triggering the password reset form using public usernames.
Grok clarified the technical nature of the campaign directly. According to the AI bot, a widespread wave of unsolicited X password reset emails was hitting many accounts, with attackers mass-triggering the form through public usernames.
Importantly, Grok confirmed there was no confirmed system breach or mass takeover, advising users to enable Password Reset Protect through their Settings and privacy security options for stronger account protection.
